img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About the Role

أكسنتشر is seeking an experienced SOC Engineer L3 (DFIR) to join their team in Riyadh. This full-time role serves as a senior escalation point within the Security Operations Center, focusing on leading complex incident response investigations and performing digital forensics. The engineer will also drive SIEM engineering and tuning efforts to enhance detection capabilities, playing a critical role in protecting client environments.

Key Responsibilities

  • Act as the primary escalation point for complex and high-severity security incidents from L1 and L2 analysts.
  • Lead end-to-end incident response investigations, including containment, eradication, and recovery.
  • Conduct digital forensics analysis on endpoints, networks, and logs to determine root cause and impact.
  • Engineer, fine-tune, and optimize SIEM use cases, correlation rules, and alerting logic to reduce false positives and improve detection accuracy.
  • Develop and maintain incident response playbooks and SOC procedures.
  • Collaborate with the CTI team to integrate threat intelligence into detection and response workflows.
  • Provide mentorship and technical guidance to L1 and L2 analysts.
  • Prepare detailed incident reports and present findings to management and clients.

Role Context and Impact

This position is central to enhancing the security posture of client environments. The SOC Engineer L3 (DFIR) will contribute directly to improving incident response capabilities and strengthening detection mechanisms through advanced SIEM management and forensic analysis. The role also involves developing the skills of junior analysts through mentorship.

Work Environment

This is a full-time position based in Riyadh. The role involves working within a Security Operations Center, collaborating with various security teams, and providing support and guidance to other analysts.


Requirements

  • No experience required

Similar Jobs